Vulnerabilities > CVE-2021-42146 - Improper Handling of Exceptional Conditions vulnerability in Contiki-Ng Tinydtls 20180830

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
contiki-ng
CWE-755

Summary

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to obtain sensitive application (data of connected clients).

Vulnerable Configurations

Part Description Count
Application
Contiki-Ng
1